runtimepki

package
v0.1.59 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 14, 2026 License: Apache-2.0 Imports: 33 Imported by: 0

Documentation

Index

Constants

View Source
const (
	ClientCertificateLifetime = 24 * time.Hour
)

Variables

This section is empty.

Functions

func StartCertificateRetentionWorker

func StartCertificateRetentionWorker(ctx context.Context, pool *pgxpool.Pool)

StartCertificateRetentionWorker prunes only certificate audit inventory. It is intentionally independent from the optional automatic PKI manager so deployments that disable mTLS still converge historical certificate rows.

Types

type BindingVerifier

type BindingVerifier struct {
	// contains filtered or unexported fields
}

func NewBindingVerifier

func NewBindingVerifier(pool *pgxpool.Pool) *BindingVerifier

func (*BindingVerifier) ResolveRuntimeDeviceIdentity

func (v *BindingVerifier) ResolveRuntimeDeviceIdentity(ctx context.Context, credentialID uuid.UUID) (coreruntime.RuntimeDeviceIdentity, error)

func (*BindingVerifier) ResolveTokenOnlyRuntimeDeviceIdentity

func (v *BindingVerifier) ResolveTokenOnlyRuntimeDeviceIdentity(
	ctx context.Context,
	credentialID uuid.UUID,
	nodeID uuid.UUID,
) (coreruntime.RuntimeDeviceIdentity, error)

func (*BindingVerifier) VerifyRuntimePrincipalBinding

func (v *BindingVerifier) VerifyRuntimePrincipalBinding(
	ctx context.Context,
	credentialID uuid.UUID,
	device coreruntime.RuntimeDeviceIdentity,
) error

type ClientCertificate

type ClientCertificate struct {
	CertificatePEM      string
	CertificateChainPEM string
	TrustBundlePEM      string
	Serial              string
	FingerprintSHA256   string
	PublicKeySHA256     string
	NotBefore           time.Time
	NotAfter            time.Time
	RenewAfter          time.Time
}

type CredentialRequest

type CredentialRequest struct {
	NodeID                string   `json:"node_id"`
	DisplayName           string   `json:"display_name"`
	NodeVersion           string   `json:"node_version"`
	ProtocolVersion       int32    `json:"protocol_version"`
	RuntimeContractID     string   `json:"runtime_contract_id"`
	RuntimeContractDigest string   `json:"runtime_contract_digest"`
	Features              []string `json:"features"`
	Capacity              int32    `json:"capacity"`
	CSRPEM                string   `json:"csr_pem"`
}

type CredentialResponse

type CredentialResponse struct {
	NodeID                string    `json:"node_id"`
	AgentID               string    `json:"agent_id"`
	CertificatePEM        string    `json:"certificate_pem"`
	CertificateChainPEM   string    `json:"certificate_chain_pem"`
	TrustBundlePEM        string    `json:"trust_bundle_pem"`
	CertificateSerial     string    `json:"certificate_serial"`
	PublicKeyThumbprint   string    `json:"public_key_thumbprint"`
	NotBefore             time.Time `json:"not_before"`
	NotAfter              time.Time `json:"not_after"`
	RenewAfter            time.Time `json:"renew_after"`
	CertificateLifetimeHr int       `json:"certificate_lifetime_hours"`
}

type CredentialService

type CredentialService struct {
	// contains filtered or unexported fields
}

func NewCredentialService

func NewCredentialService(pool *pgxpool.Pool, authority *Manager, tokens RuntimeTokenValidator) *CredentialService

func (*CredentialService) Register

func (s *CredentialService) Register(api *echo.Group)

func (*CredentialService) RegisterTrustBundle

func (s *CredentialService) RegisterTrustBundle(e *echo.Echo)

type Manager

type Manager struct {
	// contains filtered or unexported fields
}

Manager owns the default self-managed Runtime trust hierarchy. CA private keys are encrypted before persistence and are shared through PostgreSQL, so HA replicas do not require operators to distribute CA files.

func NewManager

func NewManager(ctx context.Context, pool *pgxpool.Pool, cfg *config.Config) (*Manager, error)

func (*Manager) IssueClientCertificate

func (m *Manager) IssueClientCertificate(csr *x509.CertificateRequest, nodeID uuid.UUID) (ClientCertificate, error)

func (*Manager) ServerTLSConfig

func (m *Manager) ServerTLSConfig() (*tls.Config, error)

func (*Manager) Start

func (m *Manager) Start(ctx context.Context)

func (*Manager) TrustBundlePEM

func (m *Manager) TrustBundlePEM() string

type RuntimeTokenValidator

type RuntimeTokenValidator interface {
	ValidateRuntimeToken(context.Context, string, ...string) (db.AgentRuntimeToken, error)
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL